CVE-2023-22834

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Configurations

Configuration 1 (hide)

cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-27 00:15

Updated : 2023-11-07 04:07


NVD link : CVE-2023-22834

Mitre link : CVE-2023-22834

CVE.ORG link : CVE-2023-22834


JSON object : View

Products Affected

palantir

  • contour
CWE
CWE-862

Missing Authorization

CWE-425

Direct Request ('Forced Browsing')